User wise GPO not applying

Posted on 2011-04-19
Last Modified: 2012-06-27

I need to block internet access for some users , i would like to it thourhg gpo by changing proxy settings.  Created a ou called internet blocked and added those users .  Created a gpo as no internet and  done the settings  as under user congiguration > internet explorer settings> connections> proxy settings  given a proxy ip as and port 3030 excluded some intranet ips for accessing internal applications.

My intenetion is to block these users from the domain on any pc with their credential.  But this is not happening.  one more settings i tried and disable to change lan settins under  uerconfigruation>administrative templates>internet explorer> Dsable changing connection settings  and this is getting applied!

Blocked the inheritance from default domain policy and made this one as enforced.  The users are domain users only .   under sercurity filtering added these users  and authenticated  users too.  

Nothing works pls help.
Question by:mylat
    LVL 14

    Accepted Solution

    You shouldn't control GPO membership by creating OU's, it's better to create a Security Group and apply this GPO to this group, that way any user you don't want to have internet access just place them in the group.

    To accomplish this setting I've attached a pic for Windows 2003 GPO.  If its Win2k8 let me know as its different.

    Link the GPO at the OU level where your normal users are.  You can force the GPO.  Let me if this works? Proxy

    Author Comment

    Thank you for your  comment .  Can we apply gpo to a security group directly? it should be in an ou right ? There are 2 dcs from me one is windows 2008 r2 and other is windows 2003 r2.
    LVL 14

    Assisted Solution

    Yes, you can apply the GPO so it only applys to users who are members of a paticuler group.  In GPMC, click on the GPO, and in the right hand pane click on the scope tab.  Remove authenticated users from the Security Filtering and add in your group.

    You link the GPO to an OU - but the GPO will only apply to users who are in the group, because you have removed "authenticated users".

    Configure the GPO on the Win2k3 DC

    Author Comment

    please close this
    LVL 67

    Expert Comment

    This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.

    Featured Post

    PRTG Network Monitor: Intuitive Network Monitoring

    Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

    Join & Write a Comment

    I have been working as System Administrators since 2003. I recently started working as a FreeLancer and was amazed to find out that very few people are taking full advantage of their Windows Server Machines. Microsoft Windows Server comes with so…
    Redirected folders in a windows domain can be quite useful for a number of reasons, one of them being that with redirected application data, you can give users more seamless experience when logging into different workstations.  For example, if a use…
    This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
    This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

    728 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now